BETA Free plan, no card required.

Somebody changed it. Nobody remembers who.

Kronikl records every change in your Azure tenant — the resource, the role grant, the policy edit — with the configuration either side of it. Read-only, and set up in about ten minutes.

Connect your tenant How it works

Read-only · Microsoft Entra ID admin consent · No agents and nothing to install

Azure tells you what is running. Not what changed.

  • 90 days

    Azure Activity Log keeps 90 days of operations — a line saying a write happened. It does not keep what the configuration was before the write, or after it.

  • 14 days

    Azure Resource Graph keeps 14 days of change records. Past two weeks, the question when did this setting change has no answer in the portal.

  • Nobody.

    Nobody remembers who widened the NSG rule. The auditor is asking about March, and the person who would know left in April.

No agents. No scripts. No infrastructure.

Kronikl reads your tenant through Azure's own APIs and keeps its own history. There is nothing to install in your subscriptions.

  1. Admin consent, in the browser

    A Global Administrator grants three read-only Microsoft Graph application permissions. Kronikl stores no password and no client secret for your tenant — access is a federated credential, exchanged per call.

  2. An Azure RBAC role, in your terminal

    Kronikl needs a read-only role on the subscriptions you want tracked. It writes the exact command for Azure CLI, PowerShell, Terraform or Bicep, and you run it — Kronikl never grants itself access. Built-in Reader is the default.

  3. Recording starts

    Kronikl records the current state of everything visible, then keeps watching on a frequent schedule, so new changes appear shortly after they happen.

Who changed this Azure resource, and when

One feed of every change in your tenant — resources, policy, roles and privileged access. Filter it by anything on the row. No query language.

  • Every administrative write, in one feed.
  • Failed attempts are kept — a denied delete is exactly the row you want.
  • Platform noise is hidden by default, never deleted.
  • Every filter lives in the URL, so the view you are looking at is a link you can paste into a ticket.

Configuration drift, side by side

Pick any two points in a resource's history and see exactly which properties differ — by property path, not two walls of JSON.

  • Walk back through every snapshot until the setting was right.
  • The fields Azure rewrites on its own are folded away, so a real change is not buried under churn.
  • Add one rule to an NSG and you see one added rule, not twelve moved ones.
  • A configuration that goes A → B → A is a revert, and Kronikl keeps all three snapshots. Reverts are never collapsed away.

An export your auditor can actually use

One request produces the whole range as CSV or JSON — nineteen columns, streamed, with no row cap. Whatever the auditor asked for, that is what comes out.

  • The export includes the routine platform events the timeline hides, with routine as a column — the reader decides, not us.
  • If your plan's window clamped the range you asked for, the response says so explicitly rather than quietly returning less.
  • Provenance travels with each row: whether a fact came from Azure or was reconstructed by Kronikl, and when.
  • Give an external auditor an account scoped to one subscription or one resource group, and the export honours that scope like every other screen.

Get told, instead of finding out

Set a rule and Kronikl watches for it: a privileged role granted, a resource deleted in a production resource group, an NSG opened to the internet, a policy assignment removed, or an elevation outside your working hours. A burst of matching events becomes one notification, not four hundred.

It can only read, and you can switch it off

Connecting a production tenant is a real decision. Here is exactly what it grants.

  • Read-only, always

    The role Kronikl asks for is Reader, or a custom role whose only permission is */read. There is no write or delete anywhere in it.

  • You grant the access, not us

    Kronikl prints the command and your administrator runs it. It cannot give itself permissions inside your tenant.

  • Nothing stored, revoked in one click

    No secret, no password and no API key against your tenant. Withdraw consent and access stops — within minutes, and at the outside the life of one short-lived Microsoft token.

How Kronikl compares

If you use the Azure portal

Configuration history
14 days of change records, no config14 or 90 days, with the config either side
Comparing two points in time
Not availableProperty-level diff
Reading the Activity Log
Raw JSON, one subscription at a timeOne filterable feed across subscriptions

If you already have a SIEM

Who it is for
A SOC analystWhoever administers the tenant
Query language
KQL, and rules to maintainFilters and a URL
Point-in-time config diff
Not what log search is forThe core of the product

If you are weighing an audit suite

Scope
AD, file shares, on-premises, AzureAzure only, and deeper for it
Getting started
Agents, collectors, a projectAdmin consent and one role assignment
Commitment
An annual contractA free plan and no card

Free to start, $100/month for Pro

Free stays free — 14 days of queryable history, one subscription, no card. Pro is $100 per month for the 90-day window and unlimited subscriptions.

Free

$0/month

A real tenant, real history, no card.

  • 14 days of queryable history
  • The full timeline, diff, resources and export
  • Alert rules, and their findings in the app
  • Unlimited team members from your tenant
Connect your tenant

Questions before you sign up

Can Kronikl change anything in my Azure environment?

No. Every permission we request is read-only.

How quickly does a change appear?

Usually within a couple of minutes of Azure recording it.

Where is my data stored?

In the United States, on Microsoft Azure, encrypted in transit and at rest.

What happens to the noisy platform events?

Hidden by default, and one click away when you want them.

What happens to my data if I stop using Kronikl?

Close your account from inside Kronikl — an owner can do it — and we delete everything within seven days, then confirm by email. If you simply stop signing in, nothing is deleted: your history stays until you ask. You can also stop collection from a tenant on its own, which leaves the history you already have readable and exportable.

Stop guessing what changed.

Connect a tenant and Kronikl starts recording within minutes. Nothing to install, nothing to run, and no card to start.

Connect your tenant Read the security section first